secrets-auditScan projects and codebases for exposed secrets, API keys, tokens, passwords, and sensitive credentials. Detects hardcoded secrets in source code, config fil...
Install via ClawdBot CLI:
clawdbot install charlie-morrison/secrets-auditGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Sends data to undocumented external endpoint (potential exfiltration)
Webhook → https://hooks\.slack\.com/services/T[A-Z0-9]+/B[A-Z0-9]+/[a-zA-Z0-9]+Hardcoded API key or token pattern found in skill definition
ghp_xxxxxxxx...Calls external URL not in known-safe list
https://hooks\.slack\.com/services/T[A-Z0-9]+/B[A-Z0-9]+/[a-zA-Z0-9]+Uses known external API (expected, informational)
Usage Guide
Loading usage data… refresh in a few seconds.
Scored Jun 24, 2026
slack.comAI Analysis
The skill's primary function is to scan for secrets, which is consistent with the Slack webhook URL pattern found; this is likely for sending audit notifications, not exfiltrating user data. The hardcoded API key pattern appears to be an example within the documentation, not a credential harvesting mechanism. No evidence of hidden instructions, obfuscation, or behavior overriding user intent was found.
Audited Apr 17, 2026 · audit v1.0
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
全面排查企业的经营风险情况,适用于供应商准入尽调、贷前风险筛查、合作伙伴背景调查等场景,全方位预警潜在经营风险,辅助决策者规避合作隐患。
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
Audit and score OpenClaw AgentSkills against structural compliance, quality standards, and OpenClaw-specific architecture patterns. Produces a 0-100 score wi...